PT-2004-1874 · Apache · Apache+1

CVE-2004-0809

·

Publicado

2004-09-12

·

Atualizado

2022-09-23

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache versions 2.0.50 and earlier
Description The issue is related to the mod dav module, which allows remote attackers to cause a denial of service by crashing a child process. This can be achieved by sending a specific sequence of LOCK requests to a location with WebDAV authoring access. The issue does not allow execution of arbitrary code and only results in a denial of service when a threaded process model is in use.
Recommendations For Apache versions 2.0.50 and earlier, consider disabling the mod dav module as a temporary workaround to prevent the denial of service. Restrict access to locations with WebDAV authoring access to minimize the risk of exploitation. Avoid using the LOCK method in affected locations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0809
DSA-558-1
RHSA-2004:463

Produtos afetados

Apache
Apache Http Server